Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. The Lounge
  3. Case insensitive passwords

Case insensitive passwords

Scheduled Pinned Locked Moved The Lounge
question
20 Posts 13 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P Pualee

    No reason for alarm... your a programmer... did you have a CS background? The size of the alphabet alone does not make the password safe or not. You can just come up with your own encoding for the password you want and as long as the string is sufficiently long, your covered. camelCasePassword --> camelucaseupassword :suss: Edit: I bet an individual encoding would be harder to break using known hashes... think... if everyone has their own encodings... then the passwords become much more random (in the eyes of the attacker) and harder to break.

    T Offline
    T Offline
    tgrt
    wrote on last edited by
    #11

    But it should make it safer. So if I generate a password 14 characters long than the password is 62 bits if it's case insensitive or 81 bits if it's case sensitive. The bank in question limits the length of the password to 14 characters. (It's 29 and 36 bits for a six character password.) The site is a little better than this, because it does allow a handful of special characters. Where am I wrong? Edit: by the way I used the Keepass password generator to give me quick and dirty relative bit strength for a sample password

    P 1 Reply Last reply
    0
    • T tgrt

      Would anyone else feel uncomfortable if their bank, a major bank, used case insensitive passwords?

      R Offline
      R Offline
      Roger Wright
      wrote on last edited by
      #12

      Nope. Heck, until a couple of years ago, my bank still used a 4-digit PIN for online banking. Any letters is a big improvement! :-D

      Will Rogers never met me.

      1 Reply Last reply
      0
      • T tgrt

        But it should make it safer. So if I generate a password 14 characters long than the password is 62 bits if it's case insensitive or 81 bits if it's case sensitive. The bank in question limits the length of the password to 14 characters. (It's 29 and 36 bits for a six character password.) The site is a little better than this, because it does allow a handful of special characters. Where am I wrong? Edit: by the way I used the Keepass password generator to give me quick and dirty relative bit strength for a sample password

        P Offline
        P Offline
        Pualee
        wrote on last edited by
        #13

        tgrt wrote:

        The bank in question limits the length of the password to 14 characters

        It's all 1's and 0's in the end. However, the limitation in length does break down my argument, now you don't necessarily have the ability of encoding .

        1 Reply Last reply
        0
        • T tgrt

          Would anyone else feel uncomfortable if their bank, a major bank, used case insensitive passwords?

          L Offline
          L Offline
          Lost User
          wrote on last edited by
          #14

          Yes. It reduces the amount of possible combinations. Would you boast over a vault with a bad lock?

          Bastard Programmer from Hell :suss: If you can't read my code, try converting it here[^] They hate us for our freedom![^]

          1 Reply Last reply
          0
          • T tgrt

            Would anyone else feel uncomfortable if their bank, a major bank, used case insensitive passwords?

            T Offline
            T Offline
            TheGreatAndPowerfulOz
            wrote on last edited by
            #15

            yep

            If your actions inspire others to dream more, learn more, do more and become more, you are a leader.-John Q. Adams
            You must accept one of two basic premises: Either we are alone in the universe, or we are not alone in the universe. And either way, the implications are staggering.-Wernher von Braun
            Only two things are infinite, the universe and human stupidity, and I'm not sure about the former.-Albert Einstein

            1 Reply Last reply
            0
            • T tgrt

              Would anyone else feel uncomfortable if their bank, a major bank, used case insensitive passwords?

              P Offline
              P Offline
              PIEBALDconsult
              wrote on last edited by
              #16

              Wait a minute... how would you know?

              1 Reply Last reply
              0
              • N Nish Nishant

                How about banks that only allow a max of 8 characters :-)

                Regards, Nish


                My technology blog: voidnish.wordpress.com

                L Offline
                L Offline
                Lost User
                wrote on last edited by
                #17

                Nish Sivakumar wrote:

                How about banks that only allow a max of 8 characters :)

                It depends if they are using rather large values of 8 or not.

                Michael Martin Australia "I controlled my laughter and simple said "No,I am very busy,so I can't write any code for you". The moment they heard this all the smiling face turned into a sad looking face and one of them farted. So I had to leave the place as soon as possible." - Mr.Prakash One Fine Saturday. 24/04/2004

                B 1 Reply Last reply
                0
                • L Lost User

                  Nish Sivakumar wrote:

                  How about banks that only allow a max of 8 characters :)

                  It depends if they are using rather large values of 8 or not.

                  Michael Martin Australia "I controlled my laughter and simple said "No,I am very busy,so I can't write any code for you". The moment they heard this all the smiling face turned into a sad looking face and one of them farted. So I had to leave the place as soon as possible." - Mr.Prakash One Fine Saturday. 24/04/2004

                  B Offline
                  B Offline
                  Brisingr Aerowing
                  wrote on last edited by
                  #18

                  Website written in FORTRAN?

                  Bob Dole

                  The internet is a great way to get on the net.

                  :doh: 2.0.82.7292 SP6a

                  1 Reply Last reply
                  0
                  • T tgrt

                    Would anyone else feel uncomfortable if their bank, a major bank, used case insensitive passwords?

                    B Offline
                    B Offline
                    Brisingr Aerowing
                    wrote on last edited by
                    #19

                    My bank is the exact opposite. The password AND the username are case sensitive. And they don't allow any special characters, just letters and numbers.

                    Bob Dole

                    The internet is a great way to get on the net.

                    :doh: 2.0.82.7292 SP6a

                    1 Reply Last reply
                    0
                    • T tgrt

                      Would anyone else feel uncomfortable if their bank, a major bank, used case insensitive passwords?

                      C Offline
                      C Offline
                      Chris Berger
                      wrote on last edited by
                      #20

                      Absolutely I would feel uncomfortable. But not for the reason that some people seem to be imagining. It's because it makes me think that they're storing my password in plaintext. Basically, I can think of two ways that my password would be case insensitive. a) is deliberate - they uppercase (or lowercase) it before hashing it. It seems pointless and silly to do this, but it causes no great loss of security. b) is accidental - they're storing my password in plaintext, and SQL string comparisons are case insensitive by default. The tendency to believe b) is what makes me uncomfortable.

                      1 Reply Last reply
                      0
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Don't have an account? Register

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • World
                      • Users
                      • Groups